I upgraded willingly so the deceptive upgrade practices, while deplorable, didn't really affect me. What does affect me is that Microsoft refuses to let me control my computer.
- If you turn off Windows Defender Real Time Protection it explicitly tells you "You can turn this off, but if it's off for a while we'll turn it back on". It turns itself on upon next reboot, it seems.
- You can't turn off Windows Update. It will always end up downloading new updates.
- Once an update is scheduled for a restart you can only delay a few times and it will then force the restart.
- You can't remove worthless apps like Microsoft Groove and OneDrive integration.
- They are continuing to try to weasel the Windows Store into my life by buying up or forcing exclusives (games), with all the drawbacks of UWP.
Microsoft, I promise I know what I'm doing and the risks and benefits of each action I want to perform. I own my hardware, I'd like to control the software I licensed. I am well aware of other OS options and I use Linux & OS X often, but neither can compare to the gaming library available on Windows which is my primary use case for my desktop.
I'm in a similar boat. I bought my child a cheap PC, it came with Windows 10, and it took a lot of careful configuration to turn off all the tracking and advertising. Then it kept nagging to update Windows 10 (what we used to call a service pack), never mind that it kept scheduling to do it overnight, would reboot and fail. Finally, I got it to download and install the latest win10, and as noted by others, it was essentially an entire re-install of the OS.
But here's where it got nasty: the user data was kept, but all of the privacy settings and default apps were reset. Actually not reset, it made you go through the OS configuration screens where it always suggests the default (share all user and browsing information with MS). The configuration was so full of dark patterns: the default is a single button on the screen, but the non default settings are accessed through an underlined link that is not very descriptive. Or turning off tracking is labeled advanced and opens another window.
This was the real scary part to me: if you are not a savvy user and know to turn off these things, Win 10 defaults will track everything you do, including your browsing activity ("to provide suggestions"). These basic privacy settings should not be hiding behind dark patterns.
> - They are continuing to try to weasel the Windows Store into my life by buying up or forcing exclusives (games), with all the drawbacks of UWP.
A neat trick is if you download something from the Windows App store and sign in for the first time without using an MSN account to log into your PC, it will ask you something like "Do you want to use this login with all Microsoft services?" And if you say yes then your login is converted to the MSN account, which you won't realize until you next need to log in.
Learned that the hard way on my primary development machine. Have a crazy long randomly generated password for my Microsoft account. Had to reset password on a different machine.
With the latest update... many of my settings for existing features were changed. My desktop background was reset to default, my choice of browser was switched back to Edge, and my taskbar icons were reset...
"Oh, cool, I was wondering where I put Edge... now I'm so happy it's back!" Wait, that's not what I said at all.
I assume all the privacy settings I tried to change to be in my favor were reset as well, and there's about 8 GB of random "Windows.old" crap cluttering my my SSD.
The update took 30 minutes on a modern computer and no less than 3 restarts to get up onto "Anniversary Edition" -- mind you there was very little to no warning it was coming, just "You have an update."
I've stood up for Microsoft numerous times with friends, but man... I don't trust them, they don't respect my settings, or my intelligence, and they are treating my hardware like they own it. I'm done with their crap... Made the decision to just deal with Apple's crap now and Ubuntu's crap now.
Couldn't tell anyone what the benefits of Windows 10 Anniversary Edition are; so the ROI just isn't there for me in putting up with Microsoft any more.
Next step: In the OEM license, include a provision that the ownership of the hardware is transferred to Microsoft and you're granted a license to plug a screen and use devices.
1 is the reason I'll never use Win10. I don't trust Linux, even in a VM. Too many people have access and I am forced to assume it's insecure by default. My assumption will never change.
2 is inconsequential. I can use a "dark theme" in Win7; all I did was disable Aero and set up my desktop the same way I had since Win95.
3 Firefox
4 Okay, good reason.
5 The Win10 (actually, WinVista+) start menu is pointless.
You trust a closed source OS from a developer already proven to be willing to engineer backdoors and lie about it over an open-source OS? Can you explain your reasoning?
I don't actually _trust_ either one, but I would certainly rank Windows below Linux.
Also note that the linux runtime in Win10 is not installed or activated by default; you need to put the OS in developer mode and install it yourself. If an attacker can do that externally, he already owns your system.
Everything you've listed is addressable by enterprise users in an AD environment. I.E., Microsoft's real customers. Using a copy of Windows 10 with no Cortana, Auto-updates, Groove, or Windows Defender right now.
Yes. If you want that control, all you have to do is buy a subscription [0]. $7 per month isn't that much to be able to control your own computer is it? That's only $84 per year or $252 every 3 years -- it's practically a discount for buying an upgrade every 3 years!
It comes with Office365 too! I'd totally buy this for the added control over home edition, but it looks like Microsoft only sells this license in bulk to big businesses in my region. Then again...it turns out that you can upgrade to enterprise without a valid key [1] and that there are no real penalties for doing this [2]. So, shrug, I guess they don't want my money - and I'm not going to use an OS that turns me into a mineable dataset.
I don't unfortunately and I haven't got around to trying it yet. If you (or anyone else on HN) finds something that works, could you post the link here?
What is "AD environment"? Sounds like maybe what I want.
I want no updates or changes of any kind without my knowledge. Indeed, before any change, I want to backup the relevant boot partition so that I can restore it if any changes are harmful or doubtful.
For Cortana, when I looked at it, everything it has I have a lot better with just my favorite programmable text editor and a few simple macros.
Uh, to reply, I have to edit my post! So, here is my reply!
My now very old and crude understanding is that Active Directory is a standard part of Windows Server and plays the role of essentially the old MIT system Kerberos for authentication.
My concern is that ASAP I need to take my Web site software currently in alpha test and have it go live. For that, for maybe just a few, first users, I could use just my development computer running Windows 7 Professional. But, also on that computer I intend to have at least one bootable partition with Windows Server.
So, with Windows Server, I could be running Microsoft's Active Directory. Fine with me.
Then that means that somehow all my bootable partitions with Windows 7 or Windows Server will not get updates or changes without my explicit permission? Hope so.
Or maybe your point is just that the automatic updates don't apply to Windows Server? I would believe so.
If you weren't familiar enough with Microsoft's products to immediately recognize that the acronym "AD" within the context of Microsoft anything, means Active Directory, then you are thousands of dollars, and possibly multiple years away from moving in that direction.
I know a lot of the fundamental concepts in computing, many from when they were nearly new. I knew nearly all the concepts long before Windows, 10, 8.1, 8, 7, Vista, XP, 2000, or NT. I didn't learn the concepts in the context of Microsoft or Windows. So, I learned the concepts before I ever saw any Microsoft acronyms.
E.g., I first learned about Kerberos from one of the first papers about it, an article in Scientific American. I learned about RSA and public keys, of course, usable with Kerberos, near the beginning. I still have the source code for an early version of Kerberos. And I learned about and used authentication, capabilities, and access control lists back not too far from their origins in Multics. Sure, later IBM called some of that Resource Access Control Facility (RACF) -- saw some of that, too.
So, at one point Microsoft in Windows Server wanted some authentication, capabilities, with encryption, etc. so borrowed Kerberos and got Active Directory. Fine. So far I've never seen even a single word of Microsoft's Active Directory documentation but likely already understand nearly all the main purposes and core ideas. For working with the actual code, I suspect that I can get the dozen or so operations I need with examples and documentation and, then, be okay on Active Directory.
Uh, in a very significant sense, Microsoft and Windows are an example of the old biology ontogeny recapitulates phylogeny. That is, each organism as it develops from fertilization goes through stages that closely repeat how the species evolved. Well, as Windows grew from Windows 95 to Windows 10, it stayed close to the development of the core ideas in computing, e.g., multiple virtual memory, demand paged, protected, with gate segments, etc., embedded operating systems with an hierarchical file system. They stayed close to the ideas in the Mach kernel. And they are staying close to the ideas in virtual machine. Some of the hardware ideas include instruction caches, data caches, multi-way set associative caches, cache invalidates, page-segment tables, address translation look aside buffers, micro-code, instruction pipelines, speculative execution, out of order execution, parallel execution, etc. I understood all of those well long before I ever touched a PC.
I have a friend with a background a little less than mine who got good with Windows Server, Active Directory, Exchange, running an e-mail server, etc. all fairly quickly. So can I.
There is an issue: I'm trying to be successful with my startup. For that, I need to learn some about computing. Okay. But I'm not trying to be a broadly competent computer professional. The difference is, I just want to know enough for my startup and am not trying to know enough for everything everyone else might encounter. So, a good computer professional can be eager to learn everything in sight (early in my career, I did a lot of that). But as a startup entrepreneur, I want to minimize how much I learn. Significant difference.
Okie doke, well, the main point being that Microsoft usually doesn't just want you to buy one thing and call it a day.
Ya gotta buy the server-class license for the OS. And then ya gotta buy a quantity of client licenses for the Professional/Business version of the OS. And then they all need some applications, and then those applications need some non-OS-application server software. And then those application servers need isolation, so each one needs a server OS license of its own, and then, and then, and then...
Setting up windows servers takes time. Not because it's particularly difficult, or technical, but because you are not in control of the process. The software distribution is in control, and will try to phone home. You will wait while the software tries to contact the Microsoft mothership, and the software will not ask you whether such activities are even possible. It will time-out network connections, and possibly refuse to work, before even prompting you about skipping steps. You may need to make phone calls. These are facts about using Microsoft as part of enterprise infrastructure in a business environment.
The entry-level prices for what you seek are here:
You will spend more than that. By the time you feel comfortable with your configuration, it will be time to upgrade, introducing forced changes to your process, and you will spend more money. You will spend more money on more Microsoft products, and also on peripheral costs which may not be expected but will likely be driven by compatibility choices.
And by the way, Windows 7? They will not even sell you that anymore. Mocrosoft's goal in life is to retire that version of their operating system, and require migration to newer versions.
More to the point, though, all of this was their old business model, more than a decade ago. They are no long interested in this sort of sales pitch, unless you are The Government, or a Financial Institution. Nowadays, they want your servers on their cloud (Azure). It may be cheaper doing that. If you are an addict, already hooked on Microsoft, and there's no going back, consider exploring those options.
If you must be in possession of physical hardware, and if you must run stand-alone systems for the purposes of testing and developing your latest thing, Microsoft gets very expensive very fast, in terms of both time and money.
I see so many people stuck in the gaming situation and there are no practical solutions, the only way out involves an entire industry changing direction together. I'd like to see a video card manufacturer (probably AMD since they seem to be the underdog in a 2 dog fight) start a Linux-first campaign, even if it's only for select cards.
AMD already is making a good open source driver for Linux, and both AMD and nVidia has been making proprietary drivers for Linux for a while.
Also AMD seemly releases some "Pro" features for workstation on Linux first.
The problem of Linux gaming is not the graphics drivers, in fact this part has been working "ok" for a while now.
The problem with Linux gaming is:
1. Audio is still a mess, the fastest audio library still is OSS4 (not 3), that won't ever get in the mainstream distributions (sometimes it is even explicitly banned and will get you banned from forums and irc servers if you ask about it), JACK still is finnicky to work with, PA is still buggy and slow, and ALSA although much better now, is also too slow and has terrible API (while coding for OSS, any version, is very easy).
2. Desktop is still a pain to setup, even the most "GUI-happy" distros still have problems here and there, when I asked some random people about it, I got outright hostile replies, people telling me they deliberately don't want to make Linux easier, because they don't want "dumb people using something they are not worth using", mind you, this wasn't once, or in one community, more than one person shared this view with me.
3. Some people in the community are outright hostile to games, and even sabotage efforts to make games work better, I saw a flamewar where one guy was claiming games were purely dumb entertainment, and that people that played games weren't not only inferior humans, but people that deserved Windows, as punishment. This guy was of the opinion that no GUI server should ever support exclusive fullscreen properly, that instead they should have all features focused on "Work" features always.
4. Lots of other random hardware is a pain to setup on Linux, even things that usually don't cross people minds, for example I couldn't figure how to make Linux properly support my motherboard Super I/O chip, that is even a common one, I even convinced the manufacturer to give me the chip datasheet, but I couldn't even figure to what project I would need to contribute code. (as for what the Super I/O chip does: control the motherboard sensors, fans and power distribution, including voltage values and regulation commands on my motherboard)
The only way this is going to work, is if some company with a lot invested in the gaming ecosystem (e.g. Valve) spends some of those billions of dollars to make a ground up OS from the Linux kernel, similar to Android.
The ONLY usable Linux "distros" at the moment are hobbyist projects. This includes Ubuntu, Debian, Mint, etc. etc.
No serious company or individual that relies on a predictable and reliable user experience is going to use any of the modern flavors of Linux. Someone has to spend the money to do this right, and do it right once and for all.
Obviously, Stallman was right and every closed source OS is going the way of 1984 by making the users the product and gathering every single keystroke and mouse click in order to monetize you. As a convenient side effect, they are creating a perfect turn-key totalitarian system that could be used to devastating effect with the necessary political will.
Greed is good? Apparently it isn't good enough, because Gabe Newel would rather hoard his billions than spend on critical infrastructure for his company's future.
A Linux OS needs to be built from the kernel by professional and well paid developers who don't fork every single repo if they don't like tab spacing.
Democracy doesn't work in engineering, it doesn't work in business, and it probably doesn't work in politics. Linux works because Linus is a "benevolent" dictator. That's why the kernel is such a marvel of engineering. Because he oversees every commit. The same needs to happen downstream.
I would love to use Linux for gaming, but the vast majority of the games I play and plan to play are Windows only despite the advances made in Linux gaming systems. I ran Steam OS for a while and I play some games in Ubuntu but Linux Gaming just isn't there yet, at least for me.
This likely won't change (again, for me) because not only would more games need to be released on Linux into the future, but a significant portion of my existing gaming library would need to be ported. I have spent years and considerable money building my gaming library and with minor hiccups almost all of them can be run on modern Windows due to its focus on backwards compatibility along with the efforts of the community.
I suppose there is a breaking point where there are enough newer games being released, older ones ported, and continuing annoyances from Microsoft that I would use Linux as my main gaming OS. I wonder how long that will take? It's frustrating to say the least as gaming is far and away my favorite hobby.
Keep Win 7 for your Windows games library and buy new stuff only if it has announced SteamOS/Linux support? That's what I am doing now. The more of us behaving like that, the sooner we can make Linux more attractive and profitable to game makers. Many game engines already have a Linux support, so it should be easier to port/test games to Linux.
I am running SteamOS on Zotac NEN with currently 39 AAA games and frankly barely spend any time on Windows for gaming, and prefer buying games that have announced SteamOS support. I also have Win 7 & Win 10 on that computer just in case I need it for Uplay/Origin stuff or DX12-only (1TB M.2 SSD with 500GB for SteamOS, 250GB for either Win 7 and Win 10 and 2TB HDD for storage). Surprisingly, everything works just fine (I had one complete freeze in the past few months). It can work nicely even in 4K in Tomb Raider, GRID Autosport or Metro, though on lower details. Frankly, I know I can get 25% more fps on Windows, but what difference would it make for me to run GRID at 120fps when it runs on 90fps already? And Linux can only get better so why sticking to Windows?
With a few word substitutions I could use this to describe my experience on Android.
Background: highly experience Linux user. On a budget, and move, needed something for basic connectivity. Wanted a larger tablet.
9-10" Nexus devices nowhere to be found in brick-and-mortar stores (and hard to come by online as well). Almost always crippled by pathetically small storage.
My Samsung Tab A isn't rootable, flashable, had an absolutely useless userland installed (Termux has helped some with that), and now insists that the tools I've used to try enforcing my will are malware, and won't stop nagging me over this.
The default featureset is so pathetically poor that I could neither figure out where disk space was being used, or address moving things elsewhere, necessary for an OS upgrade. Which now fails on account of rooting attempts.
I'm pretty fucking pissed at Google, Android, and Samsung at this point.
And that's before getting to hardware issues.
Offering computers to the public at large is apparently an intractable problem.
(There's another set of gripes I could write about OS X. And I just commented on Debian's fucking up 20 year old mouse drivers.)
You're trying to root Android to get what you want, and Samsung doesn't want you to do that.
Unfortunately there's no better option out there. If you had an iphone you'd have even less control over your phone.
I'm in the same boat, I have a Samsung at the moment because the hardware is nice, but I'm pretty dissatisfied with the bloatware and IMO Android in general is getting further and further away from satisfying the power users.
The default Gallery app is a UI abomination, and you can't completely replace it with something better (the Camera app will always use the Samsung Gallery App to review photos, there's no way to change it).
I'm aware iOS isn't a better option. There's a reason I've not gone that route.
I'm absolutely irate at Samsung and Google/Android. Once again, the latter company is absolutely burning up goodwill it's engendered among technical users.
I'm keeping my eye on alternatives. There's a Spanish-made Ubuntu phone which might be suitable.
Otherwise, a small ultralight notebook could be useful, but from whom? I've run Thinkpads for nearly 20 years, but find current offerings abominable. I don't care for Apple hardware precisely because of keyboards and mouse/trackpad options.
Samsung's iron fist over apps is similarly pathological.
> You can't remove worthless apps like Microsoft Groove and OneDrive integration.
You can, it's just not super-easy. I've done both. Groove was pretty easy but OneDrive took a few steps.
I almost have file explorer configured in a good way for me -- it actually seems much more flexible than previous versions even if half that flexibility is only available in regedit.
OneDrive comes back to the File Explorer after each Windows 10 big update, even if you disable its icon with the registry editor. The same happens to the library folders (Videos, Pictures etc.).
Yes, many customizations are lost with the "big" updates, including disabling telemetry and cortana as well as tons of settings. That's because they aren't _really_ updates; they are complete OS installs. Your old windows directory is literally renamed to windows.OLD.
This is my largest complaint with Windows 10. In particular, it resets file associations on every major patch. Supposedly this is because applications are no longer supposed to set associations themselves, the user is supposed to do it individually for a file of each type through the Windows interface, and Win10 is "fixing broken associations".
Seeing more negative news about Win 10 on HN interests me. HN, what I regard, a big developer news site - I wonder if Microsoft cares.
I am sure and probably stating the obvious here. Developers are a group Microsoft does care about - devs eventually drives some of the cogs in their grand scheme. Making noise here will get their attention, more than making noise on some consumer forum.
Most of it seems completely misguided if you ask me. I'm no fan of all the tracking stuff, but lets be real. Everyone in here with an iPhone or an Android phone has the same experience yet i don't see them complaining that their iphone/android device updates itself, has tracking info and locks them into stores and such. It only seems unfair when MS does it.
I remember the day when people used to be enthusiastic about their computer and saw updates not just as things getting in the way. For example, the recent win10 update for anniversary update. Are people really bitching their finally getting a native browser with extensions that is fast and has gesture/touch capability second to none on the tablet form facter? are people really pissed they're getting linux subsystem with Ubuntu 14.04 built in? are people really pissed that the store experience has improved drastically that the apps you buy work on xbox, pc, phone, tablet and hololens?
I don't get it. Groove is awesome. Its updated biweekly now and the developers are on twitter accepting feedback. OneDrive works well.. the nagging of onedrive can be uninstalled by not using the desktop app..
i won't go into every detail, but the experience of windows 10 is only as good as you make it out to be. I think most people are just largely misguided at what MS is trying to achieve and if they honestly don't like it, they don't have to buy it.
BTW, the upgrade stuff was pretty hoaky too but again, i for the life of me can't find a reason not to upgrade if the upgrade was offered. It's like having an ios device and swearing to stay on iOS 8 just because or having a linux PC and sticking to debian 6 just because.
> i don't see them complaining that their iphone/android device updates itself
You can choose not to update in both of these cases.
> people used to be enthusiastic about their computer ...
I'm not upset at those features being available. I am upset about them being added without any input from me and without a chance to stop them from being installed. I have no use for most of what you mention, I don't want them installed, and if they are installed without my consent I want to be able to remove them. I own my computer, not Microsoft.
> the nagging of onedrive can be uninstalled by not using the desktop app
You have to regedit to remove OneDrive from Explorer.
> if they honestly don't like it, they don't have to buy it.
Many people didn't buy it and were upgraded unknowingly. I did buy it, but that doesn't mean I cannot be upset at the current situation.
> for the life of me can't find a reason not to upgrade if the upgrade was offered
That's your choice, and many others. Neither you nor Microsoft should override those choices. If someone does choose to upgrade to 10 that also doesn't mean they must further consent to every other new decision Microsoft makes for Windows.
Hoaky? I'd go with deceptive, misleading, shady or dishonest instead of hoaky.
So you really think it's even in the ballpark of ok to force an update on people?
Personally, I don't have a need to update just so my OS is called Win 10 instead of Win 7. Plus I hate the Win 10 interface. I don't need touch enabled interfaces for my desktop OS.
There are many reasons why not to upgrade. Compatibility is a major one, unsupported hardware is another. The forced tracking is another. Need I go on? That's enough reasons for me.
> Most of it seems completely misguided if you ask me. I'm no fan of all the tracking stuff, but lets be real. Everyone in here with an iPhone or an Android phone has the same experience yet i don't see them complaining that their iphone/android device updates itself, has tracking info and locks them into stores and such. It only seems unfair when MS does it.
That may sadly be true. Microsoft is following Google and Apple here but you hear surprisingly few complaints about them.
I wish that were true, but I think MS is more interested in tricking users into being locked in to their software and selling their data than caring about power users/developers.
I think it will bite them in the ass eventually. Non-techie people will follow the recommendations of power users, and they are really doing a good job of pissing off all the power users.
Your last few points are annoying for sure, but the first 3 are the result of 20+ years of Microsoft's poor reputation for security due to its prominence and numerous flaws.
I completely sympathize with Microsoft's plight here, and while you might not be among those who are constantly infected, the number of people who do end up having problems is so high that they're willing to lose you as a cost of keeping the other folks safe.
We're all safer for this, too, because fewer infected computers on the Internet means fewer proxies for spam and other malignant behavior.
I completely understand why this is the default behavior, but there should be an "I'm not a normie" switch somewhere that allows me to control my experience. The Pro edition was originally that way, but as I understand it this is no longer the case and is similarly controlling.
I wish I could upvote this about 30 times. For every real Windows security expert slash power user in the wild, there's about 30 pimple-encrusted besotted teenagers out there who just want to run some warez on their parent's computer and will click whatever setting, run whatever software and make whatever Registry edits are necessary to get the game their parents won't buy them up and running.
The typical home user is not a sysadmin, doesn't want to be a sysadmin and will not put in the effort to be a sysadmin. Microsoft is building Windows to be safe for them. This is a net good for all of us. And underneith it all, Windows is still Windows, which puts it miles ahead of its real competitors (Android, iOS and I guess ChromeOS) in terms of allowing users to really own their device.
This is all great, but I am not a typical home user and there is no option for me on the Windows Edition Menu. I can buy Home or Pro, that's it. Pro used to be the "I know what I'm doing" version but this is no longer the case. Enterprise let's you do whatever you want but requires far more investment and effort to run just so that I can control my computer.
Edit to reply to cwyers below me as I cannot reply further:
Do you honestly think that running your own Active Directory system, calling Microsoft Enterprise Sales, arguing with them and probably failing to buy a single Enterprise license, and ultimately buying a pack of Enterprise licenses I do not need is required of me to be "on the same Internet as you"? All I want is close to the level of control I can get on previous versions of Windows which pale in comparison to any Linux distribution. Does this mean that anyone using a Linux distro that doesn't automatically update shouldn't be allowed on your internet? Surely if your computer is always up to date you have nothing to fear?
I am unsure how you are equating me to an anti-vaxxer simply because I want to control how and when my computer updates. I don't believe I ever said I do not ever want an update, I want to know what they are and control when they are applied as is standard on every other OS I know of.
I am also not making any ideological argument to privacy. In fact, I don't care too awful much about the telemetry in Windows 10. I don't really like it but I almost exclusive use my Windows machine for gaming so there isn't much I'm scared of MS finding out about there. I simply want to control how my computer works.
That's a spurious argument. What's important is that the OS forces updates _by default_.
Sure, some of the people that turn it off overestimate their own capabilities, and that will lead to infection. But that's a very small portion of the total population, the vast majority of which will leave everything set to default.
Long story, but my Surface Pro 2 wound up with Win10 Pro. The Pro version is slightly more configurable for privacy than Home, but only the Enterprise version can completely turn off the telemetry and so on. Of course Enterprise is not easily available to end-users and it is expensive.
There are some utilities available that are supposed to improve the privacy/security of Win10 installations, e.g., [0].
My wife kept asking me if she should upgrade to Win10 and I said "don't do it". Since Win8.1 will be supported until 2023 or so, it really didn't matter. Now, thankfully, the "free upgrade" period is over and she won't be nagged to do the upgrade.
After all the years in the game, we'd think MS should know better than pulling all this crap on its users.
> Note: Windows Defender may report the EXE as a trojan (Win32/Pocyx.C!cl), and may therefore prevent you from extracting the EXE to anywhere on your computer. Set up an exclusion in Settings > Update & Security > Windows Defender > Exclusions by adding the folder you intend to extract the EXE to.
I swear, it seems like people are okay with the idea of everyone BUT Microsoft have access to all their personal information on their PCs. Why would anyone install software that has this kind of recklessness in the official documentation?
Not quite sure what recklessness you are referring to. If necessary, the exception is only for the one directory the EXE is in. IIRC the program isn't really installed, it just needs to run once to make changes in firewall rules, etc., that prevent MS telemetry. AFAIK it doesn't increase external access to the computer being configured.
After making modifications, the exclusion can be deleted if desired. If you have more info about risks of using the dwt utility, I'd be real interested to hear about it.
No, uh, look, running an EXE one finds hosted on GitHub, deliberately disabling the virus-checking on that EXE file and running the EXE is the reckless behavior. Even assuming that the person who made the EXE didn't mean so maliciously, any kind of a MitM attack or other way of sureptuously putting a payload in that EXE is an attack vector.
Why is it particularly worse than downloading a binary hosted anywhere else, upstream binaries being the standard way of obtaining software on Windows?
As for the virus checker, their program's raison d'etre is making registry changes. It's not difficult to imagine that being flagged by Windows Defender is unavoidable.
I think the recent situation with SourceForge, where binaries were changed to add a malware-ridden installer[1] shows why GitHub is potentially worse than trusting some other provider. I think it's a low likelihood that something like that happens with GitHub ever, much less soon, and SourceForge has reversed that action already. But it is one reason to potentially trust binaries from a third party like that less.
But that's not really the thrust of the point. It's software from an unknown provenance, and yes, that's pretty standard for Windows but it's not great and it's getting worse all the time. Virus scanners are not a great solution, but not having them are worse. Without any kind of a checksum on that page, it's impossible to verify that the binary you have is the one that you should have. (Not that it's guaranteed that you can do so if there is a checksum.) So you're already in a bad situation, and you're turning off one of the few safeguards you have.
As for registry changes getting flagged by Defender... programs that change the registry aren't rare.[2] They do not universally share this problem. I imagine it's probably a false positive and I don't know how it could be avoided, but the proposed remedy is reckless.
Yes I'm strongly considering downgrading to 8.1. It's time for a fresh install anyways. I dread when that goes EOL because I'll have no where else to turn but whatever Windows is out at the time.
Honestly, I do not know. Telemetry isn't my biggest gripe with Windows 10, but besides that at some point the only version of Windows with security support will be Windows 10 or some descendant of it and I have no reason to believe my issues with 10 will be fixed by then.
As I said elsewhere, I'd love to be *nix only but my gaming preferences will not allow it.
I think requiring the user to boot a Linux live CD and do some voodoo would be enough. Computer would have to self destruct if you failed the steps tho.
They don't need illusions about their basic computing skills. They need a drive-by installer, malware, or "tips'n'tricks" guide that gets them to do this.
People don't need to understand tools and systems to use them. Hell, they'll use things for millennia without knowing how they work (quite literally).
If they're running malware with administrator rights, they're already lost by definition.
The kind of people that would leave settings like this at the default generally don't read tips n' tricks guides to tweaking windows. They simply don't care about that sort of thing. Of course _some_ do, as you would no doubt reply, but again it comes down to numbers-- that volume doesn't justify locking it down.
They aren't clueful users so they could be socially engineered to turn off updates, but once you get to that point why wouldn't you just get them to run a RAT as administrator? That is the end goal, after all. And once you own their system you can turn off updates yourself.
Lastly, we're talking about a switch in the GUI here-- it is already possible to completely disable telemetry and automatic updates on Windows 10. You just need to hack through the registry and group policy or use a third party tool to do it. Anyone who takes control of your computer can do it remotely.
My point was: create an easily bypassed system, and the black hats will come up with ways for people to easily bypass the system.
All the children aren't above average. Your average computer user -- even those who are otherwise intelligent and capable of handling Shit The World Throws Them -- isn't particularly tech savvy.
It's like anti-terrorism defenses. The terrorist has to get lucky once. The defender has to be lucky always. Microsoft here are the defender, and they're trying to keep idiots from fucking up their systems. No slander intended, it's just reality.
Disabling safety systems (which is what we're talking about) is simply one of many ways to make larger-scale compromises of the system far more easy to do.
I'm not saying that it's impossible for Microsoft to offer this, or that they shouldn't. And I'd be hugely frustrated myself if I had to deal with this stuff (I don't run Windows, and won't. Hell these days I barely use computers if I can possibly help it, other than my own. And I hate those increasingly as well.)
But dealing with the public at billion-plus user scale is hard.
No. The same security patches that are applied to 10 also apply all the way back to 7, and even earlier. To the extent they don't, it's because Microsoft no longer wants them to apply to 7 after the end of its support life. (Which, last I checked, hasn't happened yet.)
Do you think they rewrote the whole kernel in 10, or even a big chunk of it?
I upgraded willingly, got annoyed by that kind of stuff and downgraded again back to 7 which I'm happy with. There was nothing terrible about 10 it's probably better overall, I just didn't want the weird extras.
> You can't turn off Windows Update. It will always end up downloading new updates.
Just an idea, I don't know if it would work: there's a setting where you can tell Windows that you are on a "metered connection", which supposedly makes Windows postpone various background tasks until you tell it that you are ready for bandwidth abuse (which never happens). I doubt that this would influence any connections by third party applications, so it should do little or no harm. The question is, would Windows let itself get fooled so easily?
You can set ethernet as a metered connection in the registry and the Winaero Tweaker tool can do it for you. However, when I did it, I found manually initiated windows updates stalling on "Downloading Updates 0%" so I don't recommend that solution.
Instead, configure a group policy as documented below.
Note that Windows respects the "download only" policy but does NOT respect the "no reboot after updates" policy. To stop Windows from rebooting after installing updates, follow steps labeled #2 at the link below.
> There is probably a registry value you can change to do so though.
Thanks, but with "probably" I sense that I'm about to get into what I call "mud wrestling" or hours or days of just throwing wild guesses against a wall to see if any appear to stick. I've only got 365 days a year, and I've given away far too many of them to such mud wrestling. GOD knows I do NOT want to do more of that.
For physical things, say, an alarm clock that won't quit making a noise, often can use a big hammer or an axe to solve the problem. Too often in mud wrestling with sick-o software, I wanted such a hammer or axe.
The EFF OP and this thread have me literally just TERRIFIED that my work with Windows will have me spending a huge fraction of my time that I do NOT have mud wrestling with some version of Windows. Again, GOD knows well I do NOT want mud wrestling.
To Microsoft: I am trying, desperately trying, 12 hours a day, 7 days a week, to the limits of strength of my body, to get my software written for my Web site startup. For my software, I have 80,000 lines of typing for the real-time parts and another 20,000 for the off-line parts. I want, desperately NEED, to do the rest of the work of my startup. NO WAY do I have in addition the time, money, strength, and energy to fight Microsoft software for no good reason. I want NO updates, NO changes, without my well informed, explicit permission. I want NO data sent from my computer elsewhere without my well informed, explicit permission.
Cortana or whatever it is called? I wouldn't hit a hog in the butt with all the copies of Cortana on the planet. To me the work and objectives of Cortana are insulting, outrageous, patronizing, demeaning, intrusive, and worse. I don't want it.
What do I want from Microsoft? (1) Fix the outrageous security problems Microsoft has been struggling with back at least to XP. (2) Do much better technical writing in technical documentation of Microsoft software.
Then I want to finish my startup with no more attention to anything from Microsoft.
Speaking as a veteran Microsoft administrator, in total seriousness: buy a Mac. If you have a corporate network complete with good administrators, Windows can be made to work well enough. If you are a lone professional, Macs are secure, low-maintenance and have an OS designed by people that care about your privacy. Windows is probably not worth your time or energy right now unless there a specific piece of Windows-only software that you must use.
Okay, and when my Web site software, with several special back end servers, is all working well, what platform do I use to keep, say, an 8 core AMD processor at 4.0 GHz busy?
On Windows, I'm aiming at Windows Server (WS). My initial usage of WS will be just dirt simple. As I get revenue, for more I will pick up a phone, call an expert, maybe you, pay for an hour to walk me through the most recent issue, take notes, and then move on until the next issue.
For Windows, I have used the .NET Framework, Visual Basic .NET, ASP.NET, ADO.NET, a little of platform invoke to call some C code, etc. and, of course, Microsoft's Internet Information Server (IIS) to sit between my Web pages and the users. I wish the .NET documentation had better technical writing, but otherwise I'm from happy enough to thrilled with .NET. If I am to use .NET heavily, then I sense that to minimize mud wrestling with weak documentation and too many bugs (e.g., from trying to get .NET to run well on iOS or Linux) I should stay on Windows.
Maybe implicit in your suggestion is that I would deploy for production on some Linux system? Okay, which one? And how many loose ends, third party, open source, do it yourself issues would I encounter?
Roughly I get the impression that for high end production use of Linux, I would be nearly rolling my own operating system -- this could be wrong. I'm eager to have good information on any operating system I use, but really I want to draw a line at the operating system, compilers, etc. and not cross that line.
At this point, I about have to go ahead with Windows. Maybe I'll get some books Windows Server 101 for Dummies or some such.
As no-one else seems to have replied to the parent as I write this, let me just reassure you that if you do ever want to look into using a Linux platform for the server side of your system, it's not so big and scary.
There are lots of Linux distributions. For general purpose server work, something big and well-supported like Debian would be a sensible starting point. You can install a relatively bare bones system to start with, and then use Debian's package manager to install and keep up-to-date most other software you're likely to need without having to build anything manually yourself.
You have several decent web servers available. Apache is the 800lb gorilla, huge but does just about everything and very thoroughly documented. There are some good alternatives like Nginx and Lighttpd as well.
There are also plenty of tools that you can add to do things like load balancing and caching if you need them.
You have several decent database servers available. Postgres is a solid choice for most things if you want a traditional relational database. Again, there are plausible alternatives such as MariaDB if your needs are slightly different. The main "NoSQL" databases also tend to run on Linux if that's what you're looking for.
Almost every major programming language has tools available to run back end code in that language on a Linux system.
Basically, the only thing you give up by moving to Linux on the back end is the Microsoft-specific technologies like IIS, SQL Server, .Net and C#. (There have even been some efforts to get .Net and C# supported usefully on non-Windows platforms, but I have no experience with those so won't comment further here.)
There is obviously a learning curve to configure these things if you haven't used Linux before, so I wouldn't necessarily recommend jumping ship if you're already set up on Windows servers and comfortable administering them. But if you do ever decide to switch, there are plenty of tutorials and HOWTO guides for setting up things like web servers and databases on Linux as well, and it's the kind of thing where you could probably get up to speed on the basics within a week or two of homework and experimentation.
Nice. Thanks. I needed that. I was hoping for something like that.
Okay, if my startup becomes a big thing, then maybe I'll have the servers all on some version of Linux. For the conversion, if I could consider doing it now, then it would be easy enough for a team of a dozen if my company gets to 100+ people.
As it is, except for nonsense interruptions not due to Windows or Microsoft but would be much the same for Linux, I am a few weeks of good work from going live. I shouldn't jump ship now.
Your original post just specified "Web site", so I assumed that you'd be using an Open Source stack - mea culpa.
Without writing a long reply - I sympathize with where you are coming from. I spent 5 years as a .NET developer between admin jobs, and the apparently all-encompassing, answer-for-everything nature of the Microsoft stack was attractive. If we could have stayed inside the lines of what Microsoft wanted to provide at the time, it would have been pleasant.
One of the advantages of switching to an Open Source platform was being able to access a much wider range of options for things, including hosting. One of these is the full-service Heroku platform - there are Web developers that only deploy to Heroku, and never set up servers.
Why don't you just put a firewall between the machine you want to stay untouched and the Internet. Block all outgoing connection attempts to Microsoft servers. "Firewall block windows update" seems to return relevant results.
That seems like a good "big hammer" sort of solution to me.
Why don't you want security updates? Personally, on all OSes I use I just want security updates to happen. My time is too valuable for me to go reading about every minor security update, when I will just install it anyway.
Unfortunately, Microsoft of recent times has demonstrated that they are even willing to bundle things they want to force on you within "security" updates. Many commentators at the time suggested that this was a line they should never have crossed and will pay for in loss of trust later.
So, in this tread I mentioned that I
wanted to select when to have updates and
didn't want automatic updates and that
because of my concern that at least in
principle updates could break existing
development tools or running production
code.
So, if I'm not ready to take the time,
money, and effort to respond to such
breakage, then I want to delay updates
until I am.
In particular for my development and
production systems, an automatic update
that breaks crucial tools or working code
could be a disaster for my startup.
Okay, now we have a current example of
where a Microsoft Windows 10 update broke
old code that was working.
My main interest is my startup. So, what I really care about is my development system and, then, my production system. Since the development seems nearly done and is in alpha test, soon I will be highly interested in my production system.
One of my concerns is a standard, old one: On a system used for development or production, don't change any of the tools until are ready to accept the extra work of fixing any new problems the changes cause.
So, just delay changes to fit my work schedule. E.g., I don't want some change, intended to be good, break something in my tools or my production software. Such things have been known to happen; I haven't seen such in Windows, but at one point I was around some high end production systems where one hour of outage in a year meant that the CIO lost his bonus and two hours, his job. No joke. Walk around the raised floor? Not a chance! They were uptight. A change or update? Fine: Run it on the side for no less than six months. Well, the fundamentals of that situation have not changed.
Really, soon into production, I will want a test system on the side, put any changes on that system first, run it with the best test workload I can, and after some weeks usually implement the changes on the production systems.
On Windows, I've gotten good at using the old NTBACKUP to backup a copy of a boot partition and, later restore it. I have several such backups for my current, main boot partition.
When I get closer to production, if some automatic updates were applied to a production boot partition, I might save the partition but I definitely would restore back to the version before the updates.
My main interest is not as a consumer user but as a developer of a startup that could become serious, maybe an average of an hour a week of 75% of the people with access to the Internet -- IMHO my software has by a wide margin the best solution for a problem serious for nearly every user of the Internet. That's my main interest.
While not defending Microsoft (my first advice would be: don't use Windows), there's a free app called "ShutUp10" that allows you to fix almost everything in your list above.
Jury is not out, shutup10 turns off "official' telemetry services. Problem is MS build in telemetry into everything now, explorer, cortana, edge, crypto service or dnscache, _everything_ calls home regularly ~once per hour during ordinary use.
Only way to 99.9% block telemetry is to switch blocking all outgoing by default in firewall and whitelist what you use. This still leaves DNS exfiltration route :(
Did you read the comments where, if you do block the standard ports, the telemetry system in Win10 goes all subversive botnet-like and starts connecting on random ports to random hosts in order to get out of the firewall?
I think he talks about W10 ignoring hosts file and calling home using raw IPs if you block usual domains. This still gets blocked with firewall.
DNS is a problem tho, I dont know of any dns clients with per application whitelist functionality :( This means every program on the system can make dns queries.
afaik Windows firewall is not able to block loopback communications, can komodo?.
I dont want to give up dns caching, and since I dont know of any way to firewall localhost traffic in windows I figured only way would be in dns caching program itself.
So far only way to prevent dns tunneling I can come up with involves giving up dnscache :(. To make up lost performance you could maybe run dnsmasq on the router, or in a virtual machine? or somehow force dnscache to listen on virtual network adapter?
Why would an app developer NOT embrace a technology that would allow them to write once and run anyware from phone to tablet to desktop to tv and hololens?
Most of these people are projecting their perceived issues with the platform, not the reality thereof.
Steam still runs great on Windows 10 and Windows 10 is steams largest OS base already.
UWP solves a lot of problems with win32.. a lot. It was premature in windows 8 but has matured well with anniversary update. (being sandboxed is probably the best consumer feature ever..)
> ...from phone to tablet to desktop to tv and hololens...
You mean the Microsoft phone, Microsoft tablet, to Microsoft desktop, Microsoft (XBOX) TV and Microsoft Hololens?
Well, nobody uses Windows Phone and hardly anybody uses Windows tablets or Hololens...so that leaves XBOX and Windows desktop. I don't make games for a living, I make business apps - and no businesses are using XBOX....so there's literally no reason for me as a developer to go out of my way to build UWP apps for these business customers. Also, Win32 apps work fine on my Windows tablets.
> Most of these people are projecting their perceived issues with the platform, not the reality thereof.
Not at all. The reality is that UWP is a sandbox and I don't want to program in a sandbox. I also refuse to make programs that can only be sold through the Microsoft app store (and asking customers to enable a developer feature in order to side-load my app is out of the question.)
> UWP solves a lot of problems with win32...
It also threw away a lot of win32. A lot. But it doesn't matter to me because I'm not touching it until they loosen it up. And they will, because nobody else is touching it either.
Surface sells a lot of devices.. a few billion dollars worth a year. THere are lots of tablets out there. Pretty silly to ignore them all and be willfully ignorant about it.
Sandboxing is a good thing, it protects systems from developers. It's why even on operational tooling, a lot of teams are moving to containers to "sandbox" apps through cgroups and contain them in a re-usable fashion.
A lot of win32 apps are even being packaged for the store so they too are sandboxed having the luxury of knowing what state your app is in at all times is an awesome thing thing to developers that care about knowing that state.
I own multiple Windows tablets, so I'm certainly not being willfully ignorant.
You're being willfully ignorant that A) anybody is buying them to use UWP apps. They're not. Microsoft's app store isn't doing shit compared to Apple's or Google's. And B) that the sales numbers are anything to cheer about. They're not. Last quarter Apple did 7 billion dollars in iPads vs Microsoft's 1 billion in Surface.
Universal Windows Platform. A development platform for making apps that work similarly on regular desktop Windows as well as the touch interfaces of Surface/Windows Phone, etc.
> If you turn off Windows Defender Real Time Protection it explicitly tells you "You can turn this off, but if it's off for a while we'll turn it back on". It turns itself on upon next reboot, it seems.
I don't really see this as a negative but to each his own. You're probably better off just using Windows Defender than some third-party A/V solution anyway since they're all pretty useless.
> You can't turn off Windows Update. It will always end up downloading new updates.
While this is true prior to the AU where you could at least change it to not automatically check for updates. You would then have to explicitly check for updates but yes it would then automatically download and install them when you did.
I believe since the group policy no longer works in RS1 it will wind up always checking for updates now. You can thankfully still disable getting driver updates through Windows Update using registry tweaks.
> You can't remove worthless apps like Microsoft Groove and OneDrive integration.
No but you can disable/not use them. You can disable OneDrive in the Startup tab of the task manager.
> They are continuing to try to weasel the Windows Store into my life by buying up or forcing exclusives (games), with all the drawbacks of UWP.
I think they pushed games on UWP too early. After the AU (RS1) I'm not sure if there are any game breaking issues for UWP games anymore other than the fact that they're on the Windows Store if you consider that to be a negative.
But there's an obvious solution to this and it's simply to vote with your wallet. Don't like games using the Windows Store? Don't buy them. It's that simple.
- If you turn off Windows Defender Real Time Protection it explicitly tells you "You can turn this off, but if it's off for a while we'll turn it back on". It turns itself on upon next reboot, it seems.
- You can't turn off Windows Update. It will always end up downloading new updates.
- Once an update is scheduled for a restart you can only delay a few times and it will then force the restart.
- You can't remove worthless apps like Microsoft Groove and OneDrive integration.
- They are continuing to try to weasel the Windows Store into my life by buying up or forcing exclusives (games), with all the drawbacks of UWP.
Microsoft, I promise I know what I'm doing and the risks and benefits of each action I want to perform. I own my hardware, I'd like to control the software I licensed. I am well aware of other OS options and I use Linux & OS X often, but neither can compare to the gaming library available on Windows which is my primary use case for my desktop.